Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 599408 (CVE-2016-9186, CVE-2016-9187, CVE-2016-9188) - www-apps/moodle: Multiple vulnerabilities
Summary: www-apps/moodle: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2016-9186, CVE-2016-9187, CVE-2016-9188
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2016-11-10 16:17 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2016-11-13 13:31 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-11-10 16:17:59 UTC
Incoming CVEs
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2016-11-10 16:18:31 UTC
CVE-2016-9188 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9188):
  Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2
  allow remote attackers to inject arbitrary web script or HTML via the
  s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter
  parameters.

CVE-2016-9187 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9187):
  Unrestricted file upload vulnerability in the double extension support in
  the "image" module in Moodle 3.1.2 allows remote authenticated users to
  execute arbitrary code by uploading a file with an executable extension, and
  then accessing it via unspecified vectors.

CVE-2016-9186 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9186):
  Unrestricted file upload vulnerability in the "legacy course files" and
  "file manager" modules in Moodle 3.1.2 allows remote authenticated users to
  execute arbitrary code by uploading a file with an executable extension, and
  then accessing it via unspecified vectors.
Comment 2 Anthony Basile gentoo-dev 2016-11-13 13:28:58 UTC
commit 6a86f651594abfc160c6b6e25954774be1903ca0
Author: Anthony G. Basile <blueness@gentoo.org>
Date:   Sun Nov 13 08:28:19 2016 -0500

    www-apps/moodle: version bumps to 2.7.17, 2.9.9, 3.0.7, 3.1.3, bug #599408.
    
    Package-Manager: portage-2.3.0
Comment 3 Anthony Basile gentoo-dev 2016-11-13 13:29:33 UTC
Also the vulnerable versions are off the tree.